Skip to main content

Threats Tagged 'vpn'

View all threats tagged with 'vpn'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: vpn

Threats Tagged 'vpn'

Click on any threat for detailed analysis and mitigation recommendations

A credential theft campaign by Storm-2561 exploits SEO poisoning to distribute fake VPN clients. Users searching for legitimate VPN software are redirected to malicious websites hosting ZIP files containing trojans masquerading as trusted VPN clients. These digitally signed trojans harvest VPN credentials and exfiltrate data to attacker-controlled infrastructure. The campaign uses GitHub repositories, legitimate code-signing certificates, and sophisticated post-theft redirection strategies to avoid detection. The attack chain involves initial access through SEO manipulation, execution of malicious MSI files, credential theft via fake VPN interfaces, and data exfiltration. Defensive recommendations include enabling cloud-delivered protection, using EDR in block mode, and enforcing multi-factor authentication.

Join the discussion

An investigation using Silent Push's Traffic Origin and residential proxy data revealed a suspicious Chinese VPN provider. The analysis focused on IP address 205.198.91.155, which showed unusual traffic from Russia, China, Myanmar, Iran, and Venezuela. This IP was linked to the domain lvcha.in, hosting a Chinese-language VPN. Further investigation uncovered nearly 50 related domains promoting the same VPN, suggesting attempts to bypass country-level firewalls. The VPN's infrastructure was found to use residential proxies and had connections to various high-risk countries. This case study demonstrates the importance of verifying physical and technical behaviors of connections to protect against fraud and state-sponsored actors using stolen identities and spoofed locations.

Join the discussion

The NKNShell malware campaign involves a compromised South Korean VPN provider website used to distribute a multi-stage malware payload. The threat actor Larva-24010 deploys several backdoors including MeshAgent, gs-netcat, and a novel Go-based backdoor called NKNShell, which leverages NKN and MQTT protocols for command and control. The infection chain uses trojanized installers and PowerShell scripts, employing advanced evasion techniques such as AMSI and UAC bypasses. Additional tools like SQLMap are deployed to facilitate further exploitation. While primarily targeting Korean VPN users, the sophisticated use of blockchain-based networking protocols and multiple backdoors poses risks to any users of the compromised VPN service. The campaign's medium severity reflects its complexity and targeted nature, but it has not yet been observed exploiting widespread vulnerabilities or causing large-scale impact beyond South Korea.

Join the discussion

A recent malware campaign uses SEO poisoning on Bing to distribute a trojanized Ivanti Pulse Secure VPN client via lookalike domains. Users are tricked into downloading a malicious MSI installer that steals VPN credentials from the connectionstore.dat file. Stolen credentials are exfiltrated to a command and control server hosted on Azure infrastructure. The attack employs signed executables and referrer-based conditional content delivery to evade detection. This credential theft technique has been linked to subsequent Akira ransomware deployments. Organizations are advised to implement multi-factor authentication, conduct user awareness training, and monitor for suspicious network and endpoint activity. No CVE or known exploits in the wild are reported yet. The threat poses a medium severity risk due to credential compromise and potential ransomware follow-on attacks. European organizations using Ivanti Pulse Secure VPN are at risk, especially in countries with high adoption of this VPN solution and critical infrastructure sectors.

Join the discussion
0

MuddyWater, an Iranian cyber espionage group linked to Iran's Ministry of Intelligence and Security, is deploying DCHSpy, an Android surveillanceware, amid the Israel-Iran conflict. DCHSpy is distributed via malicious VPN apps promoted on Telegram channels and is capable of extensive data collection including WhatsApp data, contacts, SMS, files, location, call logs, audio recordings, and photos. Recent variants have enhanced capabilities for exfiltrating data from specific files and WhatsApp. The malware's targeting appears to leverage StarLink-related lures, exploiting Iran's internet outages. DCHSpy shares infrastructure with SandStrike, another Android malware targeting Bahá’í practitioners. This threat poses significant espionage risks to individuals in conflict zones and those using Android devices in targeted regions.

Join the discussion

This analysis reveals the complex operations of Lumma affiliates within a vast information-stealing ecosystem. Affiliates utilize various tools and services, including proxy networks, VPNs, anti-detect browsers, and crypting services. The investigation uncovered previously undocumented tools and showed that affiliates often run multiple schemes simultaneously, such as rental scams, while also using other infostealers like Vidar, Stealc, and Meduza Stealer. Lumma affiliates are deeply integrated into the cybercriminal ecosystem, leveraging underground forums for resources, marketplaces, and operational support. The analysis highlights the resilience of Lumma's infrastructure and the challenges in disrupting such decentralized cybercriminal networks.

Join the discussion

A popular Chrome VPN extension, FreeVPN.One, with over 100,000 installs has transformed into spyware. Initially legitimate, the extension began capturing screenshots of users' online activities and collecting sensitive information after an update in April 2025. The spyware operates covertly, automatically taking screenshots of every webpage visited and uploading them to an attacker-controlled domain. It also exfiltrates device and location data at installation and startup. The extension's developer provided evasive responses when confronted, claiming the feature was for background scanning of suspicious domains. This incident highlights the potential risks associated with VPN services and the importance of scrutinizing even seemingly trustworthy browser extensions.

Join the discussion

Akira affiliates have been observed exploiting two common drivers as part of a suspected AV/EDR evasion effort following initial access involving SonicWall abuse. The drivers, rwdrv.sys and hlpdrv.sys, are being used to facilitate AV/EDR evasion or disablement through a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain. This behavior has been prevalent in recent Akira ransomware incident response cases. The campaign may be driven by an unreported zero-day vulnerability in SonicWall VPNs. Defenders are advised to harden SonicWall VPNs, implement recommended mitigations, and use provided YARA rules for detection and response to pre-ransomware activity.

Join the discussion

A potential zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. The attack chain begins with a breach of the SonicWall appliance, followed by post-exploitation techniques including enumeration, detection evasion, lateral movement, and credential theft. Attackers quickly gain administrative access, establish command and control, move laterally, disable defenses, and deploy Akira ransomware. The threat actors use a mix of automated scripts and manual activity, abusing privileged accounts and utilizing various tools for persistence and data exfiltration. Immediate action is advised, including disabling SonicWall VPN access or severely restricting it, auditing service accounts, and hunting for malicious activity using provided indicators of compromise.

Join the discussion

A new information-stealing malware called Gremlin Stealer, written in C#, has been identified by researchers. Advertised on Telegram since March 2025, it targets a wide range of data including browser information, crypto wallets, FTP and VPN credentials. The malware exfiltrates stolen data to a web server for publication. It can bypass Chrome's cookie V20 protection and supports various Chromium and Gecko-based browsers. Gremlin Stealer also targets cryptocurrency wallets, Telegram and Discord sessions, and system information. The stolen data is compressed into a ZIP archive and sent to the attacker's server using a Telegram bot. This evolving threat highlights the need for robust cybersecurity measures to protect against such information stealers.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: vpn
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses